4 ms·
Can you post full message headers somewhere? It'd be interesting which MTA was involved in delivery from the sender's side.
by SSLy 1y ago
Can you post full message headers somewhere? It'd be interesting which MTA was involved in delivery from the sender's side.
- junon 1y agoYep - https://gist.github.com/Qix-/c1f0d4f0d359dffaeec48dbfa1d40ee9 https://gist.github.com/Qix-/c1f0d4f0d359dffaeec48dbfa1d40ee...
- SSLy 1y agolet's see the header of interest: Received: from npmjs.help by smtp.mailtrap.live
- XxgodReixX88 1y agowhat about it?
- alexellisuk 1y agoHow did simply opening this email in something like Gmail or a desktop client result in it being able to compromise NPM packages under your control? I'm just curious - and as a word of warning to others so we can learn. I may be missing some details, I've read most of the comments on the page.
- junon 1y agoI clicked the link like a genius :)
- alexellisuk 1y ago:-( How did the link hijack your password/2fa? Or did you also enter some stuff on the form?
- osa1 1y agoI don't understand. The link could've come from anywhere (for example from a HN comment). How does just clicking on it give your package credentials to someone else? Is NPM also at fault here? I'd naively think that this shouldn't be possible. For example, GitHub asks for 2FA when I change certain repo settings (or when deleting a repo etc.) even when I'm logged in. Maybe NPM needs to do the same?
- koil 1y agoAs OC mentioned elsewhere, it was a targeted TOTP proxy attack.
- hughw 1y agoSo, he clicked the link and then entered his correct TOTP? how would manually typing the url instead of clicking the link have mitigated this?
- Mogzol 1y agoThey wouldn't have manually typed the exact URL from the email, they would have just typed in npmjs.com which would ensure they ended up on the real NPM site. Or even if they did type out the exact URL from the email, it would have made them much more likely to notice that it was not the real NPM URL.
- dboreham 1y agoOP entered their credentials and TOTP code, which the attacker proxied to the real npmjs.com FWIW npmjs does support FIDO2 including hard tokens like Yubikey. They do not force re-auth when issuing an access token with publish rights, which is probably how the attackers compromised the packages. iirc GitHub does force re-auth when you request an access token.
- osa1 1y ago> They do not force re-auth when issuing an access token with publish rights, which is probably how the attackers compromised the packages I'm surprised by this. Yeah, GitHub definitely forces you to re-auth when accessing certain settings.
- nsdfg 1y agohttps://mailtrap.io/contact-details/ https://mailtrap.io/contact-details/